Thursday, February 4, 2016

Week 8--Energy Infrastructure Vulnerability

Recently, power plants in Ukraine experienced a cyber attack that turned off power for several hours. Apparently, hackers worked into the electricity plant networks, accessed control stations, and opened breakers in numerous substations, leaving 80,000 people or more in the dark. The hackers also launched a telephone denial-of-service attack, apparently trying to prevent news of the blackout from reaching the plant. Finally, attackers used malware called KillDisk to destroy data on numerous computers, rendering the operating systems unbootable. This data corruption paralyzed many of the companies' systems and prolonged the blackout. Though it was a well-orchestrated attack, the results only lasted for a few hours, and only several electric plants were affected.
This is considered the first blackout as a result of a cyberattack, and it targeted switches (breakers) connected indirectly to the Internet. In other words, this was partially an attack on IoT devices. It was also limited: if one wants to pull off a successful attack, why not attack all of the power facilities, instead of a few? Why only affect 80 thousand people? Why only for a few hours? The answers to these questions are up for grabs, but it's worth remembering that it is only the first cyberattack to cause a blackout.
Is the U.S. any better off than Ukraine, or can it happen here as well? It depends on how you look at it. The security of our grid is slightly better than over there, but our energy sector's InfoSec can sure use some work. The link mentions that 82% of IT respondents from the energy sector believed a cyber attack could cause physical damage; only 35% say they are able to track all threats on at-risk networks.
35%
If 2 in 3 IT professionals in the energy sector believe they can't track all threats, let alone protect against them, then how secure are we?
Obviously, securing the energy grid is important. This industry uses a blend of traditional computers and computer-controlled devices (like the breakers mentioned earlier), so securing energy infrastructure will require a mix of conventional computer security and IoT-related security. This is an important sector to protect, especially if an attack is likely to cause physical damage. While what happened in Ukraine may never happen again, it is foolish to bury our heads in the sand, hope for the best, and fail to take appropriate security precautions concerning vulnerabilities in energy infrastrucature.

No comments:

Post a Comment